Skip to content

Legal

Data Safety

Last updated: August 7, 2026

A plain-language summary of what Orevalis collects, what stays on your device, and how everything is protected. The Privacy Policy is the complete reference.

Collected and linked to your account

Email address and display name — for sign-in, email confirmation, and password recovery (Supabase Authentication).

User identifiers — a Supabase user ID and a RevenueCat customer ID.

Financial records — only if you're signed in, backed up to private cloud storage so they can be restored (see the Privacy Policy's "Financial data backup and restore" section).

Purchase history and entitlement status — processed by RevenueCat to unlock and restore Premium.

Receipt images/files — only if you attach them and only backed up to private cloud storage when you have Premium.

Support messages you send us.

Local storage, with cloud backup for signed-in accounts

Manually entered financial records — Spaces, transactions, bills, balances, categories, merchants, notes, purchase feelings, goals, planning data, and transaction locations — are stored on your device, and, if you're signed in, may also be backed up to our cloud service provider so they can be restored. See the Privacy Policy for exactly what's included.

Local notification settings for bill reminders, and your theme, language, and biometric-lock preference stay device-local and are not part of the cloud financial backup.

A location you add to a transaction is stored on your device and may be included in your cloud financial backup like other transaction details — but when you view a map preview of it or open it in a maps app, the underlying coordinate or address is passed to Apple's or Google's map service at that moment, as described in the Privacy Policy's Location section.

Never collected

Bank credentials (there is no bank connection to give them to).

Complete payment card information (Apple and Google process payments).

Biometric data (your device's OS performs Face ID / fingerprint checks; the app receives only pass/fail).

Protection and control

Data is encrypted in transit. Cloud receipt backups live in a private storage bucket restricted by authenticated access controls and row-level security.

There is no advertising SDK, no sale of personal data, and no sharing for behavioral advertising.

You can export supported app data, delete individual receipts, delete local records, and delete your entire account in-app or via the Delete Account page.